668
VMScore

CVE-2017-15047

Published: 06/10/2017 Updated: 28/08/2020
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The clusterLoadConfig function in cluster.c in Redis 4.0.2 allows malicious users to cause a denial of service (out-of-bounds array index and application crash) or possibly have unspecified other impact by leveraging "limited access to the machine."

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redislabs redis 4.0.2

Vendor Advisories

Debian Bug report logs - #878076 redis: CVE-2017-15047: Insufficient input validation in the clusterLoadConfig function Package: src:redis; Maintainer for src:redis is Chris Lamb <lamby@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 9 Oct 2017 15:21:01 UTC Severity: normal Tags: securi ...
The clusterLoadConfig function in clusterc in Redis 402 allows attackers to cause a denial of service (out-of-bounds array index and application crash) or possibly have unspecified other impact by leveraging "limited access to the machine" ...